Support » Plugin: WP Job Manager » Hackers try to establish a Job with Admin account

  • Resolved freemono99212

    (@freemono99212)


    Hi!
    There must be bug, because Hackers are able to establish a Job, via the admin account and force the system to send a Publication message. Basically the Job will not be published, because of the restriction, but the email message goes trough, that a new job is published.

    The page I need help with: [log in to see the link]

Viewing 6 replies - 1 through 6 (of 6 total)
  • Plugin Support Deric (a11n)

    (@dericleeyy)

    When you mention restriction, are you referring to the enabling Moderation in Settings > Job Submission?

    If this is the case, you will still get an email whenever a job is submitted. It will say something along the lines of:

    A new job listing has been submitted to My WordPress Site. It is awaiting approval by an administrator in WordPress admin.

    What does the email that you received say?

    Thread Starter freemono99212

    (@freemono99212)

    Hi!

    – The moderation setting is enabled, but the email says, “The job is published and can be viewed by the public”. But in fact, the job is not published, because of the moderation setting.

    We have established are very strong security, with fail2ban connected to cloudflare via API, inclusive WAF firewall and until know there is no further issue. May other have not the knowledge to establish such a security, so may you have look in your code!

    Best

    Plugin Support Deric (a11n)

    (@dericleeyy)

    Was this a one-time occurrence or do you get the same “The job is published and can be viewed by the public” email for every pending job?

    Thread Starter freemono99212

    (@freemono99212)

    No! For the legal JOB SUBMISSIONS, I receive the email as mention previously:

    “A new job listing has been submitted to My WordPress Site. It is awaiting approval by an administrator in WordPress admin.”

    Best

    Plugin Support Jay (a11n)

    (@bluejay77)

    Hi @freemono99212,

    Thank you for your continued patience, and I’m sorry for the late reply.

    It’s a bit hard for us to understand how exactly some people are exploiting job submission by an admin account. Do you mean they hacked your admin account? Are they simply sending users an email that says that the job is published and they are trying to trick users?

    If you believe your site was hacked, we suggest you use this guide which will help you start cleaning up your hacked site:

    https://wordpress.org/support/article/faq-my-site-was-hacked/

    Based on what you’ve told us, the regular job submission settings seem to be working as expected, and the job is not published, so we do not have any plans to make any changes yet.

    I hope that helps! Let us know if you have any other questions.

    Plugin Support Jay (a11n)

    (@bluejay77)

    Hi there,

    It has been more than one week since we have heard from you, so I’m marking this topic as resolved.

    But if you have any further questions or need some more help, you’re welcome to reply here or open another thread.

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Hackers try to establish a Job with Admin account’ is closed to new replies.